711
|
7.2 |
HIGH
Network
|
prisna
|
google_website_translator
|
The Prisna GWT – Google Website Translator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.11 via deserialization of untrusted input from the 'pri…
Update
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-8514
|
2024-10-3 04:59 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
712
|
5.4 |
MEDIUM
Network
|
themexclub
|
oneelements
|
The OneElements – Best Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.3.7 due to insufficient input sa…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-9068
|
2024-10-3 04:55 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
713
|
5.4 |
MEDIUM
Network
|
devfarm
|
wp_gpx_maps
|
The WP GPX Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sgpx' shortcode in all versions up to, and including, 1.7.08 due to insufficient input sanitization…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-9028
|
2024-10-3 04:45 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
714
|
5.4 |
MEDIUM
Network
|
wpzoom
|
wpzoom_shortcodes
|
The WPZOOM Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'box' shortcode in all versions up to, and including, 1.0.5 due to insufficient input sanitiza…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-9027
|
2024-10-3 04:42 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
715
|
5.4 |
MEDIUM
Network
|
graphicsly
|
graphicsly
|
The Graphicsly – The ultimate graphics plugin for WordPress website builder ( Gutenberg, Elementor, Beaver Builder, WPBakery ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SV…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-9069
|
2024-10-3 04:37 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
716
|
7.2 |
HIGH
Network
|
freelancer-coder
|
wordpress_simple_html_sitemap
|
The WordPress Simple HTML Sitemap plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 3.1 due to insufficient escaping on the user supplie…
Update
|
CWE-89
SQL Injection
|
CVE-2024-7385
|
2024-10-3 04:35 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
717
|
8.8 |
HIGH
Network
|
infoblox
|
nios
|
Infoblox NIOS through 8.5.1 has a faulty component that accepts malicious input without sanitization, resulting in shell access.
Update
|
NVD-CWE-noinfo
|
CVE-2023-37249
|
2024-10-3 04:35 |
2023-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
718
|
7.5 |
HIGH
Network
apache
|
inlong
|
Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0.
The attacker could bypass the current logic a…
Update
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2023-34434
|
2024-10-3 04:35 |
2023-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
719
|
9.8 |
CRITICAL
Network
apache
|
shiro
|
Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used together with APIs or other web frameworks that route re…
Update
|
CWE-22
Path Traversal
|
CVE-2023-34478
|
2024-10-3 04:35 |
2023-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
720
|
8.8 |
HIGH
Network
|
apache
|
shardingsphere
|
Deserialization of Untrusted Data vulnerability in Apache ShardingSphere-Agent, which allows attackers to execute arbitrary code by constructing a special YAML configuration file.
The attacker needs…
Update
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2023-28754
|
2024-10-3 04:35 |
2023-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|